CVE-2009-1586

Shemes Grabit < 1.7.2 - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Jeremy Brown · perllocalwindows
https://www.exploit-db.com/exploits/8637
exploitdb WORKING POC VERIFIED
by Gaurav Baruah · perllocalwindows
https://www.exploit-db.com/exploits/8612

Scores

EPSS 0.4368
EPSS Percentile 97.5%

Details

CWE
CWE-119
Status published
Products (9)
shemes/grabit 1.5.0 beta
shemes/grabit 1.5.1 beta
shemes/grabit 1.5.2 beta
shemes/grabit 1.5.3 beta
shemes/grabit 1.6.1 beta
shemes/grabit 1.6.2 beta
shemes/grabit 1.7.1 beta
shemes/grabit 1.7.2 beta (2 CPE variants)
shemes/grabit < 1.7.2
Published May 07, 2009
Tracked Since Feb 18, 2026